Impact
A missing authentication check in a critical function of Windows Remote Desktop Services permits an attacker who already has authenticated system access to raise their privileges locally. The flaw can allow the attacker to execute code or perform actions with higher rights than their initial account, potentially jeopardizing the confidentiality, integrity, or availability of the affected system. The weakness is classified as CWE‑306, reflecting the failure to enforce required authentication.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1) across multiple processor architectures, and Microsoft Windows Server 2019, 2022, and 2025 (both standard and Server Core installations). All listed versions are susceptible to the vulnerability as identified by Microsoft in their update guide.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, but the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. Based on the description, the most probable attack vector is a local authenticated user who can exploit the unattended RDS function; remote exploitation is not indicated. The lack of a network‑level vulnerability reduces the attack surface but still poses a serious threat to systems with active RDS deployments.
OpenCVE Enrichment